HomeCirculars › RBI/2011-12/611

RRBs Must Strengthen IT and IS Governance: RBI Directive

No longer current — withdrawn, no replacement on file yet
Source: Reserve Bank of India · RBI/2011-12/611 · issued 19 Jun 2012 · ~1 min read
Quick answerRBI directs all Regional Rural Banks to implement robust IT and Information Security governance frameworks, referencing IDRBT's manual, and ensure Board-level oversight of governance, security, and business continuity.
The rule, in the simplest words
How it plays out — a real example

Ramesh, an IT-governance officer in Indore, ensures that the bank's IT system is secure and up-to-date, following the RBI's directive. He works closely with the bank's IT team to implement the IDRBT manual and conducts regular security audits to prevent cyber threats. This helps the bank maintain business continuity and protect its customers' sensitive information.

What changed

RBI issued a circular on June 19, 2012, reiterating the importance of IT and IS governance structures as highlighted in the Monetary Policy Statement 2012-13. It calls on RRBs to adopt appropriate frameworks and systems, referencing the IDRBT document on organizational structure for IT in banking.

What it means for you

RRBs must now prioritize IT governance and information security at the Board level, moving beyond mere compliance to strategic oversight. This directive aims to enhance resilience against cyber threats and ensure business continuity, aligning RRBs with broader banking sector standards.

Historical instruction — do not use for current compliance. This is what was required at the time; it no longer reflects current RBI requirements. If no replacement rule is linked above, that only means none is recorded on our register yet — it does not prove no later applicable rule exists. Confirm on the official RBI source below.

What banks were required to do at the time

Who it affects

All Regional Rural Banks (RRBs), Board of Directors of RRBs, IT and Information Security teams of RRBs, Senior management of RRBs

❓ Common questions

Regulatory timeline

Built from our lineage records — each fact carries its provenance; missing history simply is not shown (never guessed).

What is the IDRBT document mentioned in the circular?

It is a reference manual titled 'Organizational Structure for IT in the Indian Banking Sector' prepared by IDRBT, which provides guidance on setting up IT governance structures.

Does this circular apply to commercial banks or only RRBs?

This specific circular is addressed to all Regional Rural Banks (RRBs), but similar expectations apply to other banks via the Monetary Policy Statement.

What are the key areas the Board must focus on?

The Board must give adequate attention to governance, information security, and business continuity planning.

📜 This document’s life story (1 recorded event, each backed by RBI’s own words)
Repealed by RBI/2025-26/100 — Consolidation of Regulations — Withdrawal of circulars (28 Nov 2025)
RBI’s words: “Official withdrawal register entry #99: RPCD.CO.RRB.BC.No.87/03.05.33/2011-12 — "Monetary Policy Statement 2012-13 - IT and IS Governance Structures" dated June 19, 2012”
📜 Read the original circular — full text as issued by RBI
RBI/2011-12/611 RPCD.CO.RRB.BC.No.87/03.05.33/2011-12 June 19, 2012 The Chairmen All Regional Rural Banks (RRBs) Madam / Dear Sir, Monetary Policy Statement 2012-13 - IT and IS Governance structures Please refer to the paragraphs 121-123 of the Monetary Policy Statement 2012-13, wherein we have emphasized the importance of implementing IT and IS Governance structure in banks. It is expected that all banks adopt appropriate frameworks for both IT and IS Governance and put in place the proper structure and systems. Accordingly, we request you to take up suitable steps at your end in this regard and ensure that the issues relating to governance, information security and business continuity get adequate attention at the Board level. In this regard, the document prepared by IDRBT on the ‘Organizational Structure for IT in the Indian Banking Sector’ can serve as a reference manual. 2. Please acknowledge receipt. Yours faithfully (C.D.Srinivasan) Chief General Manager
Reproduced for reference with acknowledgment — Source: Reserve Bank of India · RBI/2011-12/611 · issued 19 Jun 2012. The plain-English explanation above is BankPulse’s own independent summary.
🧰 Tools — save, print, templates & related

💬 Banker Discussion

Discuss this circular with fellow bankers — reply, upvote what helps, report what doesn’t belong. Be professional; no client data. Views are the commenter’s own, not BankPulse’s.

Loading comments…
BankPulse Compliance Evidence Pack — generated 03 Aug 2026 · status cross-checked against RBI’s official withdrawal register (refreshed weekly).
Official RBI source: https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=7285&Mode=0 — Plain-English summary by BankPulse (bankpulse.ai), reviewed by our expert reviewer, CA Amit Jain. Independent platform, not affiliated with the Reserve Bank of India; is our own plain-English paraphrase, not RBI’s original wording.
Public beta — plain-English informational summaries. Always verify against the official RBI source (circular number cited on every page) before making compliance, credit, treasury, audit, or operational decisions. · Join our WhatsApp channel ↗